Information Disclosure in Eclipse BIRT Due to Host Header Manipulation
CVE-2023-0100
8.8HIGH
What is CVE-2023-0100?
Eclipse BIRT allows for the retrieval of reports using an absolute HTTP path due to a misconfigured default setting. Specifically, if the HTTP Host header matches the value specified in the __report parameter, reports can be accessed without proper authorization. This occurs most notably in environments lacking appropriate virtual host configurations, such as default setups in Apache Tomcat. The issue was identified and resolved in Eclipse BIRT version 4.13, ensuring that such unauthorized access cannot be exploited.
Affected Version(s)
Eclipse BIRT (Business Intelligence Reporting Tool) 2.6.2
Eclipse BIRT (Business Intelligence Reporting Tool) < 4.13
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved